CVE-2020-11941: OS Command Injection
An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11941?
CVE-2020-11941 is a vulnerability in Open-AudIT 3.2.2 that allows OS command injection in the Discovery module.
How severe is CVE-2020-11941?
CVE-2020-11941 has a severity rating of 8.8, which is considered high.
What software versions are affected by CVE-2020-11941?
Open-AudIT version 3.2.2 is affected by CVE-2020-11941.
How can I fix CVE-2020-11941?
To fix CVE-2020-11941, update Open-AudIT to version 3.3.0 or newer.
Are there any additional references for CVE-2020-11941?
Yes, you can refer to the following links for more information: 1. [Packet Storm Security Advisory](http://packetstormsecurity.com/files/157476/Open-AudIT-3.2.2-Command-Injection-SQL-Injection.html) 2. [Open-AudIT Release Notes for v3.3.0](https://community.opmantek.com/display/OA/Release+Notes+for+Open-AudIT+v3.3.0) 3. [Core Security Advisories](https://www.coresecurity.com/advisories/open-audit-multiple-vulnerabilities)